All Apps and Add-ons

Splunk DB Connect Version 3 Inputs on Search Heads

Venkat_16
Contributor

We have DB Connect Version 2 on our Search Head Cluster. We face frequent Connection refused Error Code 111
and would like to move to DB Connect Version 3.

From the Splunk DB Connect Version 3 documentation, we understand that DB Inputs needs to moved to Heavy Forwarders.
We currently do NOT have Heavy Forwarders in our infrastructure.

We have DB Batch inputs, can we use like below and run as scheduled report instead?

| dbxquery ... | collect ...

Is this OK to implement this? Has anyone tried like this and were successful? Should we live with DB Connect Version 2?

0 Karma

Richfez
SplunkTrust
SplunkTrust

Are you using search head clustering or just individual search heads? (It makes no difference if you hae or do not have indexer clustering, that's not a problem, only search head clustering).

0 Karma

Venkat_16
Contributor

We have Search Head Cluster and we have scheduled DB inputs in current version DB Connect v2. We want to upgrade to v3, however still like to have the scheduled DB inputs on the search heads, because we do not have heavy forwarders.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...